Sensitive-Data Safe Automation Loop
How can this automation create value without exposing sensitive data? Use this when an automation idea touches customer, employee, supplier, pricing, or employer-sensitive information. Sensitive-Data Safe Automation Loop Decision to make: How can this automation create value without exposing sensitive data? Decision owner: Governance lead with process owner, data owner, security, and automation builder. Working-session setup: - Timebox: 60 min working session - People in the room: Business owner, governance lead, system or data owner, and security or legal when required. - Preparation: Decision-room prep: validate the baseline, risks, costs, and accountable owner first. Context: [Paste your notes, excerpts, draft, meeting transcript, CRM fields, proposal text, public research, or examples here.] Context I should provide: - Automation idea - Workflow - Data fields - Users - Outputs - Tool environment - Retention rules Safety boundary: - Use only information I provide in this conversation. - Do not infer personal, confidential, regulated, pricing, customer, employee, or supplier facts. - If the material belongs in an approved enterprise environment, tell me before analyzing it. Instructions: Act as a sensitive-data automation reviewer. Analyze the workflow below. Classify the data, remove unnecessary fields, propose a safe automation pattern, define monitoring and retention, and recommend proceed, sanitize, isolate, approve, or stop. Run the session in this order: 0. Inspect the context. If a missing fact could materially change the recommendation, ask no more than five focused questions and wait. If I ask you to continue, mark each missing fact as unknown. 1. Map the workflow: Describe the action, user, decision, input, output, and downstream system. 2. Classify data: Identify personal, confidential, regulated, commercial, and employer-sensitive fields. 3. Minimize input: Remove or tokenize fields that are not required for the decision. 4. Choose the safe pattern: Use approved tools, retrieval boundaries, redaction, human review, or isolated processing. 5. Set monitoring: Define logging, access, retention, failure escalation, and periodic review. Evidence rules: - Separate supplied facts, interpretations, assumptions, and unknowns. - Reference the exact note, excerpt, metric, or example supporting every material claim. - Show the strongest credible counterargument to the recommendation. - Do not invent customer facts, benchmarks, financial numbers, policy approvals, or system access. - Do not turn missing evidence into a confident recommendation. - Keep the answer useful for Governance Lead. Output contract: A safer automation design with minimum data, approved environment, controls, and monitoring. Return: 1. BLUF: the decision, recommendation, or draft in plain language. 2. Evidence table: claim, supplied evidence, confidence, and gap. 3. Assumption ledger: what is assumed and how to verify it. 4. Counterargument: the strongest reason the recommendation may be wrong. 5. Decision record: decision status, accountable owner, next action, and due date or trigger. 6. Evidence still needed: only the gaps that could change the decision. 7. Stop condition: state when the work is complete and when it must pause. Evidence checklist: - Data classification - Minimized field list - Approved environment - Access control - Retention rule - Monitoring owner Human operating ritual: - Start with data minimization, not tool preference. - Ask what the model truly needs to know. - Document the fields intentionally excluded. Do not use this loop when: Do not treat the output as legal, security, privacy, or policy approval. A human authority must approve the final decision and the operating environment. Stopping condition: Stop when the workflow can run with the minimum safe data or is explicitly rejected.
Key takeaways
- How can this automation create value without exposing sensitive data?
- A safer automation design with minimum data, approved environment, controls, and monitoring.
- Stop when the workflow can run with the minimum safe data or is explicitly rejected.
- Data classification
- Minimized field list
Canonical URL: https://juanbeltran.ch/operating-loops/sensitive-data-safe-automation-loop